EIP-2026-114651
PRE-CVEZubrag Smart File Download 1.3 - Arbitrary File Download
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114651. PoCs published by Aodrulez.
AI-analyzed exploit summary This is a technical writeup describing a null byte injection vulnerability in 'File Download 1.3' PHP script, allowing remote attackers to bypass file extension restrictions and download arbitrary files. The exploit leverages a null byte (%00) followed by an allowed extension to trick the script into serving unauthorized files.
Description
Zubrag Smart File Download 1.3 - Arbitrary File Download
Exploits (1)
This is a technical writeup describing a null byte injection vulnerability in 'File Download 1.3' PHP script, allowing remote attackers to bypass file extension restrictions and download arbitrary files. The exploit leverages a null byte (%00) followed by an allowed extension to trick the script into serving unauthorized files.